Compare commits

..

No commits in common. "c8" and "c9-beta" have entirely different histories.
c8 ... c9-beta

7 changed files with 158 additions and 118 deletions

2
.gitignore vendored
View File

@ -6,4 +6,4 @@ SOURCES/06-5e-03
SOURCES/06-8f-08
SOURCES/microcode-20190918.tar.gz
SOURCES/microcode-20191115.tar.gz
SOURCES/microcode-20260512.tar.gz
SOURCES/microcode-20260812.tar.gz

View File

@ -6,4 +6,4 @@ bcf2173cd3dd499c37defbc2533703cfa6ec2430 SOURCES/06-2d-07
adf8b6aa2718ff16f3d19d34ec389270073d2b5e SOURCES/06-8f-08
bc20d6789e6614b9d9f88ee321ab82bed220f26f SOURCES/microcode-20190918.tar.gz
774636f4d440623b0ee6a2dad65260e81208074d SOURCES/microcode-20191115.tar.gz
8bce31d77318afd87dd07e46704661f910bc746a SOURCES/microcode-20260512.tar.gz
0503052a878b397bda69325d7f23149aab28c172 SOURCES/microcode-20260812.tar.gz

View File

@ -1,6 +1,5 @@
From b493d78adacdfbc920b64540380899fea56518d3 Mon Sep 17 00:00:00 2001
From eaf18fcce1e3bd41f270207413f0ad3f80dc1177 Mon Sep 17 00:00:00 2001
From: Eugene Syromiatnikov <esyr@redhat.com>
Date: Tue, 18 Feb 2025 20:17:49 +0100
Subject: [PATCH 16/17] releasenote.md: use new lines consistently
The empty lines are pretty inconsistent in the latest releases. Apply
@ -12,14 +11,14 @@ the following rules uniformely throughout the release notes:
Signed-off-by: Eugene Syromiatnikov <esyr@redhat.com>
---
releasenote.md | 38 ++++++++++++++++++++++++++++++--------
1 file changed, 30 insertions(+), 8 deletions(-)
releasenote.md | 37 +++++++++++++++++++++++++++++--------
1 file changed, 29 insertions(+), 8 deletions(-)
diff --git a/releasenote.md b/releasenote.md
index 0cdfa20..3c700b5 100644
index f75be84..431ac91 100644
--- a/releasenote.md
+++ b/releasenote.md
@@ -164,6 +165,7 @@
@@ -455,6 +455,7 @@ All ADL, RPL, SPR, EMR, MTL, ARL Microcode patches previously released in May 20
- Security updates for [INTEL-SA-01079](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01079.html)
- Updated security updates for [INTEL-SA-01097](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01097.html)
- Updated security updates for [INTEL-SA-01103](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01103.html)
@ -27,7 +26,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Intel® Core™ Ultra Processor](https://cdrdv2.intel.com/v1/dl/getContent/792254) for details.
- Update for functional issues. Refer to [14th/13th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
- Update for functional issues. Refer to [12th Generation Intel® Core™ Processor Family](https://cdrdv2.intel.com/v1/dl/getContent/682436) for details.
@@ -173,7 +175,6 @@
@@ -464,7 +465,6 @@ All ADL, RPL, SPR, EMR, MTL, ARL Microcode patches previously released in May 20
- Update for functional issues. Refer to [Intel® Xeon® D-2700 Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/714071) for details.
- Update for functional issues. Refer to [Intel® Xeon® D-1700 and D-1800 Processor Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/714069) for details
@ -35,7 +34,7 @@ index 0cdfa20..3c700b5 100644
### New Platforms
None
@@ -230,6 +231,7 @@ None
@@ -521,6 +521,7 @@ None
- Security updates for [INTEL-SA-01103](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01103.html)
- Security updates for [INTEL-SA-01097](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01097.html)
@ -43,7 +42,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Intel® Core™ Ultra Processor](https://cdrdv2.intel.com/v1/dl/getContent/792254) for details.
- Update for functional issues. Refer to [13th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
- Update for functional issues. Refer to [12th Generation Intel® Core™ Processor Family](https://cdrdv2.intel.com/v1/dl/getContent/682436) for details.
@@ -271,7 +273,6 @@ None
@@ -562,7 +563,6 @@ None
- Security updates for [INTEL-SA-01038](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01038.html)
- Security updates for [INTEL-SA-01046](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01046.html)
@ -51,7 +50,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Intel® Core™ Ultra Processor](https://cdrdv2.intel.com/v1/dl/getContent/792254) for details.
- Update for functional issues. Refer to [3rd Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/637780) for details.
- Update for functional issues. Refer to [3rd Generation Intel® Xeon® Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/634897) for details.
@@ -289,7 +290,6 @@ None
@@ -580,7 +580,6 @@ None
- Update for functional issues. Refer to [Intel® Processors and Intel® Core™ i3 N-Series](https://cdrdv2.intel.com/v1/dl/getContent/764616) for details.
- Update for functional issues. Refer to [Intel® Atom® x6000E Series, and Intel® Pentium® and Celeron® N and J Series Processors for Internet of Things (IoT) Applications](https://cdrdv2.intel.com/v1/dl/getContent/636674) for details.
@ -59,15 +58,15 @@ index 0cdfa20..3c700b5 100644
### New Platforms
None
@@ -337,7 +337,6 @@ None
@@ -628,7 +627,6 @@ None
- Update for functional issues. Refer to [Intel® Pentium® Silver and Intel® Celeron® Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/336562)
-
### New Platforms
None
@@ -356,6 +355,7 @@ None
| Processor | Stepping | F-M-S/PI | Old Ver | New Ver | Products
@@ -649,6 +647,7 @@ None
- Security updates for [INTEL-SA-01051](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01051.html)
- Security updates for [INTEL-SA-01052](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01052.html)
- Security updates for [INTEL-SA-01036](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html)
@ -75,7 +74,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [5th Gen Intel® Xeon® Processor Scalable Family](https://cdrdv2.intel.com/v1/dl/getContent/793902) for details.
- Update for functional issues. Refer to [4th Gen Intel® Xeon® Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/772415) for details.
- Update for functional issues. Refer to [14th & 13th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
@@ -388,6 +388,7 @@ None
@@ -681,6 +680,7 @@ None
| SPR-SP | E4/S2 | 06-8f-07/87 | 2b000590 | 2b0005c0 | Xeon Scalable Gen4
| SPR-SP | E5/S3 | 06-8f-08/87 | 2b000590 | 2b0005c0 | Xeon Scalable Gen4
@ -83,7 +82,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20240312](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20240312)
### Purpose
@@ -421,9 +422,6 @@ None
@@ -714,9 +714,6 @@ None
- Update for functional issues. Refer to [Intel® Pentium® Silver and Intel® Celeron® Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/336562) for details.
- Update for functional issues. Refer to [Intel® Pentium® Silver and Intel® Celeron® Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/634542) for details.
@ -93,7 +92,7 @@ index 0cdfa20..3c700b5 100644
### New Platforms
| Processor | Stepping | F-M-S/PI | Old Ver | New Ver | Products
@@ -540,6 +538,7 @@ None
@@ -835,6 +832,7 @@ None
| TGL-H | R0 | 06-8d-01/c2 | 00000046 | 0000004e | Core Gen11 Mobile
| TGL-R | C0 | 06-8c-02/c2 | 0000002c | 00000034 | Core Gen11 Mobile
@ -101,7 +100,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20230808](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20230808)
### Purpose
@@ -877,6 +876,7 @@ None
@@ -1172,6 +1170,7 @@ None
- Security updates for [INTEL-SA-00657](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00657.html)
- Security updates for [INTEL-SA-00614](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00614.html)
@ -109,7 +108,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Intel® Xeon® Processor Scalable Family Specification Update](https://www.intel.com/content/www/us/en/processors/xeon/scalable/
xeon-scalable-spec-update.html?wapkw=processor+specification+update) for details.
@@ -909,11 +909,13 @@ None
@@ -1204,11 +1203,13 @@ None
None
@ -123,7 +122,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Second Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/338848) for details.
- Update for functional issues. Refer to [Intel® Xeon® Processor Scalable Family Specification Update](https://www.intel.com/content/www/us/en/processors/xeon/scalable/xeon-scalable-spec-update.html?wapkw=processor+specification+update) for details.
- Update for functional issues. Refer to [Intel Atom® C3000 Processor Product Family Specification Update](https://www.intel.com/content/www/us/en/processors/atom/atom-c3000-family-spec-update.html?wapkw=processor+specification+update) for details.
@@ -979,6 +981,7 @@ None
@@ -1274,6 +1275,7 @@ None
None
@ -131,7 +130,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20220419](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20220419)
### Purpose
@@ -1006,6 +1009,7 @@ None
@@ -1301,6 +1303,7 @@ None
- Security updates for [INTEL-SA-00528](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html)
- Security updates for [INTEL-SA-00532](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00532.html)
@ -139,7 +138,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Third Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/637780) for details.
- Update for functional issues. Refer to [Second Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/338848) for details.
- Update for functional issues. Refer to [Intel® Xeon® Processor Scalable Family Specification Update](https://www.intel.com/content/www/us/en/processors/xeon/scalable/xeon-scalable-spec-update.html?wapkw=processor+specification+update) for details.
@@ -1088,6 +1092,7 @@ None
@@ -1383,6 +1386,7 @@ None
- Security updates for [INTEL-SA-00442](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00442.html)
- Security updates for [INTEL-SA-00464](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00464.html)
- Security updates for [INTEL-SA-00465](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00465.html)
@ -147,7 +146,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Third Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/637780)for details.
- Update for functional issues. Refer to [Second Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/338848) for details.
- Update for functional issues. Refer to [Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/613537) for details.
@@ -1189,6 +1194,7 @@ None
@@ -1484,6 +1488,7 @@ None
None
@ -155,7 +154,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20201118](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20201118)
### Purpose
@@ -1209,6 +1215,7 @@ None
@@ -1504,6 +1509,7 @@ None
|:---------------|:---------|:------------|:---------|:---------|:---------
| TGL | B1 | 06-8c-01/80 | 00000068 | | Core Gen11 Mobile
@ -163,7 +162,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20201112](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20201112)
### Purpose
@@ -1230,12 +1237,14 @@ None
@@ -1525,12 +1531,14 @@ None
None
@ -178,7 +177,7 @@ index 0cdfa20..3c700b5 100644
- Update for functional issues. Refer to [Second Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/338848) for details.
- Update for functional issues. Refer to [Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/613537) for details.
- Update for functional issues. Refer to [Intel® Xeon® Processor E5 v3 Product Family Specification Update](https://www.intel.com/content/www/us/en/processors/xeon/xeon-e5-v3-spec-update.html?wapkw=processor+spec+update+e5) for details.
@@ -1246,7 +1255,6 @@ None
@@ -1541,7 +1549,6 @@ None
- Update for functional issues. Refer to [Intel® Xeon® E3-1200 v6 Processor Family Specification Update](https://www.intel.com/content/www/us/en/processors/xeon/xeon-e3-1200v6-spec-update.html) for details.
- Update for functional issues. Refer to [Intel® Xeon® E-2100 and E-2200 Processor Family Specification Update](https://www.intel.com/content/www/us/en/products/docs/processors/xeon/xeon-e-2100-specification-update.html) for details.
@ -186,7 +185,7 @@ index 0cdfa20..3c700b5 100644
### New Platforms
| Processor | Stepping | F-M-S/PI | Old Ver | New Ver | Products
@@ -1294,6 +1302,7 @@ None
@@ -1589,6 +1596,7 @@ None
None
@ -194,7 +193,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20200616](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20200616)
### Purpose
@@ -1316,6 +1325,7 @@ None
@@ -1611,6 +1619,7 @@ None
None
@ -202,7 +201,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20200609](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20200609)
### Purpose
@@ -1360,6 +1370,7 @@ None
@@ -1655,6 +1664,7 @@ None
None
@ -210,7 +209,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20200520](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20200520)
### Purpose
@@ -1381,6 +1392,7 @@ None
@@ -1676,6 +1686,7 @@ None
None
@ -218,7 +217,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20200508](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20200508)
### Purpose
@@ -1401,6 +1413,7 @@ None
@@ -1696,6 +1707,7 @@ None
None
@ -226,7 +225,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20191115](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20191115)
### Purpose
@@ -1443,11 +1456,13 @@ None
@@ -1738,11 +1750,13 @@ None
None
@ -240,7 +239,7 @@ index 0cdfa20..3c700b5 100644
- Correction in release notes for specific processor to CFL-S only. Prior release showed as CFL-H/S.
### New Platforms
@@ -1464,6 +1479,7 @@ None
@@ -1759,6 +1773,7 @@ None
None
@ -248,7 +247,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20191112](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20191112)
### Purpose
@@ -1511,12 +1527,14 @@ None
@@ -1806,12 +1821,14 @@ None
None
@ -263,7 +262,7 @@ index 0cdfa20..3c700b5 100644
- Security updates for [INTEL-SA-00270](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00270.html).
### New Platforms
@@ -1543,6 +1561,7 @@ None
@@ -1838,6 +1855,7 @@ None
None
@ -271,7 +270,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20190618](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20190618)
### Purpose
@@ -1564,6 +1583,7 @@ None
@@ -1859,6 +1877,7 @@ None
None
@ -279,7 +278,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20190514a](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20190514a)
### Purpose
@@ -1624,6 +1644,7 @@ None
@@ -1919,6 +1938,7 @@ None
None
@ -287,7 +286,7 @@ index 0cdfa20..3c700b5 100644
## [microcode-20190514](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20190514)
### Purpose
@@ -1683,6 +1704,7 @@ None
@@ -1978,6 +1998,7 @@ None
None
@ -296,5 +295,5 @@ index 0cdfa20..3c700b5 100644
### Purpose
--
2.13.6
2.52.0

View File

@ -10,8 +10,8 @@ behaviour.
General behaviour
=================
In RHEL 8 (as well as RHEL 7 before it), there are currently two main handlers
for CPU microcode update:
In RHEL 9 (as well as in RHEL 7 and RHEL 8 before it), there are currently
two main handlers for CPU microcode update:
* Early microcode update. It uses GenuineIntel.bin or AuthenticAMD.bin file
placed at the beginning of an initramfs image
(/boot/initramfs-KERNEL_VERSION.img, where "KERNEL_VERSION" is a kernel
@ -45,10 +45,10 @@ zero-filled.
The early microcode is placed into initramfs image by the "dracut" script, which
scans the aforementioned subdirectories of the configured list of firmware
directories (by default, the list consists of two directories in RHEL 8,
directories (by default, the list consists of two directories in RHEL 9,
"/lib/firmware/updates" and "/lib/firmware").
In RHEL 8, AMD CPU microcode is shipped as a part of the linux-firmware package,
In RHEL 9, AMD CPU microcode is shipped as a part of the linux-firmware package,
and Intel microcode is shipped as a part of the microcode_ctl package.
The microcode_ctl package currently includes the following:
@ -613,7 +613,7 @@ Mitigation: microcode loading is disabled for the affected CPU model.
Minimum versions of the kernel package that contain the aforementioned patch
series:
- Upstream/RHEL 8: 4.17.0
- Upstream/RHEL 8/RHEL 9: 4.17.0
- RHEL 7.6 onwards: 3.10.0-894
- RHEL 7.5: 3.10.0-862.6.1
- RHEL 7.4: 3.10.0-693.35.1
@ -628,7 +628,7 @@ series:
Early microcode load inside a virtual machine
---------------------------------------------
RHEL 8 kernel supports performing microcode update during early boot stage
RHEL 9 kernel supports performing microcode update during early boot stage
from a cpio archive placed at the beginning of the initramfs image. However,
when an early microcode update is attempted inside some virtualised
environments, that may result in unexpected system behaviour.
@ -643,7 +643,7 @@ Mitigation: early microcode loading is disabled for all CPU models on kernels
without the fix.
Minimum versions of the kernel package that contain the fix:
- Upstream/RHEL 8: 4.10.0
- Upstream/RHEL 8/RHEL 9: 4.10.0
- RHEL 7.6 onwards: 3.10.0-930
- RHEL 7.5: 3.10.0-862.14.1
- RHEL 7.4: 3.10.0-693.38.1

View File

@ -43,25 +43,43 @@ for f in $(grep -E '/intel-ucode.*/[0-9a-f][0-9a-f]-[0-9a-f][0-9a-f]-[0-9a-f][0-
# ext_sig, 12 bytes in size
IFS=' ' read cpuid pf_mask <<- EOF
$(hexdump -s "$skip" -n 8 \
-e '"" 1/4 "%08x " 1/4 "%u" "\n"' "$f")
$(dd if="$f" ibs=1 skip="$skip" count=8 status=none \
| xxd -e -g4 | xxd -r | hexdump -n 8 \
-e '"" 4/1 "%02x" " 0x" 4/1 "%02x" "\n"')
EOF
# Converting values from the constructed %#08x format
pf_mask="$((pf_mask))"
skip="$((skip + 12))"
ext_sig_pos="$((ext_sig_pos + 1))"
else
# Microcode header, 48 bytes, last 3 fields reserved
# cksum, ldrver are ignored
IFS=' ' read hdrver rev \
date_y date_d date_m \
date_m date_d date_y \
cpuid cksum ldrver \
pf_mask datasz totalsz <<- EOF
$(hexdump -s "$skip" -n 36 \
-e '"" 1/4 "%u " 1/4 "%#x " \
1/2 "%04x " 1/1 "%02x " 1/1 "%02x " \
1/4 "%08x " 1/4 "%x " 1/4 "%#x " \
1/4 "%u " 1/4 "%u " 1/4 "%u" "\n"' "$f")
$(dd if="$f" ibs=1 skip="$skip" count=36 status=none \
| xxd -e -g4 | xxd -r | hexdump -n 36 \
-e '"0x" 4/1 "%02x" " 0x" 4/1 "%02x" " " \
1/1 "%02x " 1/1 "%02x " 2/1 "%02x" " " \
4/1 "%02x" " 0x" 4/1 "%02x" " 0x" 4/1 "%02x" \
" 0x" 4/1 "%x" \
" 0x" 4/1 "%02x" " 0x" 4/1 "%02x" "\n"')
EOF
# Converting values from the constructed %#08x format
rev="$(printf '%#x' "$((rev))")"
pf_mask="$((pf_mask))"
datasz="$((datasz))"
totalsz="$((totalsz))"
# Skipping files with unexpected hdrver value
[ 1 = "$((hdrver))" ] || {
echo "$f+$skip@$file_sz: incorrect hdrver $((hdrver))" >&2
break
}
[ 0 != "$datasz" ] || datasz=2000
[ 0 != "$totalsz" ] || totalsz=2048
@ -80,9 +98,12 @@ for f in $(grep -E '/intel-ucode.*/[0-9a-f][0-9a-f]-[0-9a-f][0-9a-f]-[0-9a-f][0-
# ext_sig table header, 20 bytes in size,
# last 3 fields are reserved.
IFS=' ' read ext_sig_cnt <<- EOF
$(hexdump -s "$skip" -n 4 \
-e '"" 1/4 "%u" "\n"' "$f")
$(dd if="$f" ibs=1 skip="$skip" count=4 status=none \
| xxd -e -g4 | hexdump -n 4 \
-e '"0x" 4/1 "%02x" "\n"')
EOF
# Converting values from the constructed format
ext_sig_cnt="$((ext_sig_cnt))"
skip="$((skip + 20))"
else

View File

@ -144,7 +144,7 @@ def read_revs_dir(path, args, src=None, ret=None):
offs = 0
while offs < sz:
f.seek(offs, os.SEEK_SET)
hdr = struct.unpack("IiIIIIIIIIII", f.read(48))
hdr = struct.unpack("<IiIIIIIIIIII", f.read(48))
ret.append({"path": rp, "src": src or path,
"cpuid": hdr[3], "pf": hdr[6], "rev": hdr[1],
"date": hdr[2], "offs": offs, "cksum": hdr[4],
@ -152,7 +152,7 @@ def read_revs_dir(path, args, src=None, ret=None):
if hdr[8] and hdr[8] - hdr[7] > 48:
f.seek(hdr[7], os.SEEK_CUR)
ext_tbl = struct.unpack("IIIII", f.read(20))
ext_tbl = struct.unpack("<IIIII", f.read(20))
log_status("Found %u extended signatures for %s:%#x" %
(ext_tbl[0], rp, offs), level=1)
@ -160,7 +160,7 @@ def read_revs_dir(path, args, src=None, ret=None):
ext_sig_cnt = 0
while cur_offs < offs + hdr[8] \
and ext_sig_cnt <= ext_tbl[0]:
ext_sig = struct.unpack("III", f.read(12))
ext_sig = struct.unpack("<III", f.read(12))
ignore = args.ignore_ext_dups and \
(ext_sig[0] == hdr[3])
if not ignore:

View File

@ -1,5 +1,4 @@
%define intel_ucode_version 20260512
%global debug_package %{nil}
%define intel_ucode_version 20260812
%define caveat_dir %{_datarootdir}/microcode_ctl/ucode_with_caveats
%define microcode_ctl_libexec %{_libexecdir}/microcode_ctl
@ -137,8 +136,6 @@ Source1000: gen_provides.sh
Source1001: codenames.list
Source1002: gen_updates2.py
ExclusiveArch: %{ix86} x86_64
Patch0001: 0001-releasenote.md-cleanup-eliminated-usage-of-U-0080.patch
Patch0002: 0002-releasenote.md-remove-excess-Release-Notes-headers.patch
Patch0003: 0003-releasenote.md-sort-the-entries-of-the-20230808-rele.patch
@ -160,9 +157,12 @@ Patch0017: 0017-releasenote.md-add-information-about-removal-of-CLX-.patch
# RHEL-only
Patch0101: 0101-releasenote.md-drop-Removed-Platforms-from-microcode.patch
BuildArch: noarch
BuildRequires: systemd-units
# hexdump is used in gen_provides.sh
BuildRequires: coreutils util-linux
# dd, hexdump, and xxd are used in gen_provides.sh
BuildRequires: coreutils util-linux /usr/bin/xxd
# gen_updates2.py requires python interpreter
BuildRequires: /usr/bin/python3
Requires: coreutils
Requires(post): systemd coreutils
Requires(preun): systemd coreutils
@ -398,7 +398,7 @@ install -m 644 "%{SOURCE193}" "%{spr_inst_dir}/disclaimer"
# SUMMARY.intel-ucode generation
# It is to be done only after file population, so, it is here,
# at the end of the install stage
/usr/libexec/platform-python "%{SOURCE1002}" -C "%{SOURCE1001}" \
/usr/bin/python3 "%{SOURCE1002}" -C "%{SOURCE1001}" \
summary -A "%{buildroot}" \
> "%{buildroot}/%{_pkgdocdir}/SUMMARY.intel-ucode"
@ -636,33 +636,52 @@ rm -rf %{buildroot}
%changelog
* Wed May 20 2026 Denys Vlasenko <dvlasenk@redhat.com> - 4:20260512-1
- Update Intel CPU microcode to microcode-20260512 release (RHEL-176241)
* Fri Aug 14 2026 Denys Vlasenko <dvlasenk@redhat.com> - 4:20260812-1
- Update Intel CPU microcode to microcode-20260812 release (RHEL-240771)
- Security advisories:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html
CVE-2025-31936
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html
CVE-2025-31938
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html
CVE-2026-20917
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html
CVE-2025-35973
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html
CVE-2026-20716
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html
CVE-2026-20760
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html
CVE-2026-20713, CVE-2026-20901
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html
CVE-2026-20707
- New microcode files (in hex):
06-cc-02: Panther Lake: revision 011b
06-cc-03: Panther Lake: revision 011b
06-b7-04: Raptor Lake: revision 0137
06-cc-02: Panther Lake: revision 011c
06-cc-03: Panther Lake: revision 011c
06-d5-01: Wildcat Lake: revision 000c
06-d7-00: Bartlett Lake: revision 0137
- Microcode files (/platform_mask shown) with revision updates (in hex):
06-8f-07/87: Sapphire Rapids: 2b000661 to 2b000670
06-8f-08/87: Sapphire Rapids: 2b000661 to 2b000670
06-ad-01/20: Granite Rapids-X: a000133 to a000142
06-ad-01/95: Granite Rapids-X: 1000405 to 1000423
06-ae-01/97: Granite Rapids-D: 1000303 to 1000307
06-af-03/01: Crestmont (Sierra Forest): 3000382 to 30003a3
06-bd-01/80: Lunar Lake: 0125 to 0126
06-c5-02/82: Arrow Lake-H: 011b to 0121
06-c6-02/82: Arrow Lake: 011b to 0121
06-cf-02/87: Emerald Rapids: 210002d3 to 210002e0
Resolves: RHEL-176241
* Wed Mar 25 2026 Denys Vlasenko <dvlasenk@redhat.com> - 4:20260227-1
- Update Intel CPU microcode to microcode-20260227 release (RHEL-159424)
- Microcode files (/platform_mask shown) with revision updates (in hex):
06-ae-01/97: Granite Rapids-D: 10002f3 to 1000303
Resolves: RHEL-159424
06-6a-06/87: Ice Lake-X: d000421 to d000433
06-6c-01/10: Ice Lake-D: 10002f1 to 1000301
06-7e-05/80: Ice Lake-L: 00cc to 00ce
06-8f-07/87: Sapphire Rapids: 2b000661 to 2b000685
06-8f-08/10: Sapphire Rapids with HBM: 2c000421 to 2c000435
06-8f-08/87: Sapphire Rapids: 2b000661 to 2b000685
06-a7-01/02: Rocket Lake: 0065 to 0066
06-ad-01/20: Granite Rapids-X: a000133 to a000151
06-ad-01/95: Granite Rapids-X: 1000405 to 1000434
06-ae-01/97: Granite Rapids-D: 10002f3 to 1000309
06-af-03/01: Crestmont (Sierra Forest): 3000382 to 30003b2
06-b5-00/80: Arrow Lake-U: 000d to 000e
06-b7-01/36: Raptor Lake: 0133 to 0137, platform bit 04 added
06-bd-01/80: Lunar Lake: 0125 to 0128
06-c5-02/82: Arrow Lake-H: 011b to 0122
06-c6-02/82: Arrow Lake: 011b to 0122
06-cf-02/87: Emerald Rapids: 210002d3 to 210002f4
* Wed Feb 25 2026 Denys Vlasenko <dvlasenk@redhat.com> - 4:20260210-1
- Update Intel CPU microcode to microcode-20260210 release (RHEL-151645)
- Update Intel CPU microcode to microcode-20260210 release (RHEL-151757)
- Microcode files (/platform_mask shown) with revision updates (in hex):
06-6a-06/87: Ice Lake-X: d000410 to d000421
06-6c-01/10: Ice Lake-D: 10002e0 to 10002f1
@ -694,11 +713,11 @@ Resolves: RHEL-159424
06-c5-02/82: Arrow Lake-H: 011a to 011b
06-c6-02/82: Arrow Lake: 011a to 011b
06-cf-02/87: Emerald Rapids: 210002c0 to 210002d3
Resolves: RHEL-151645
Resolves: RHEL-151757
* Mon Nov 24 2025 Denys Vlasenko <dvlasenk@redhat.com> - 4:20251111-1
- Fix typo in /usr/share/microcode_ctl/ucode_with_caveats/intel-06-8f-08/config
- Update Intel CPU microcode to microcode-20251111 release (RHEL-128250)
- Update Intel CPU microcode to microcode-20251111 release (RHEL-128199)
- New microcode files (in hex):
06-ae-01: Granite Rapids-D: revision 1000273
- Microcode files (/platform_mask shown) with revision updates (in hex):
@ -808,11 +827,11 @@ Resolves: RHEL-151645
* Tue Jun 10 2025 Denys Vlasenko <dvlasenk@redhat.com> - 4:20250512-1
- Add a caveat to provide ability to persistently disable SPR-EE updates
beyond 0x2b0005c0 on systems where absence of latency spikes
is more important than lack of the latest CVE mitigations (RHEL-95245)
is more important than lack of the latest CVE mitigations.
- Update Intel CPU microcode to microcode-20250512 release, addresses
CVE-2024-28956, CVE-2025-20103, CVE-2025-20054, CVE-2024-43420,
CVE-2025-20623, CVE-2024-45332, CVE-2025-24495, CVE-2025-20012
(RHEL-92231)
(RHEL-94294, RHEL-91231, RHEL-91224, RHEL-91224, RHEL-91239)
- Addition of 06-8f-04/0x10 microcode (in
intel-06-8f-08/intel-ucode/06-8f-08) at revision 0x2c0003f7;
- Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
@ -1032,8 +1051,9 @@ Resolves: RHEL-151645
- Update Intel CPU microcode to microcode-20250211 release, addresses
CVE-2023-34440, CVE-2023-43758, CVE-2024-24582, CVE-2024-28047,
CVE-2024-28127, CVE-2024-29214, CVE-2024-31068, CVE-2024-31157,
CVE-2024-37020, CVE-2024-39279, CVE-2024-39355, CVE-2024-36293 (RHEL-79195,
RHEL-79197, RHEL-79198, RHEL-79213, RHEL-79216):
CVE-2024-37020, CVE-2024-39279, CVE-2024-39355, CVE-2024-36293 (RHEL-79182,
RHEL-79186, RHEL-79187, RHEL-79242, RHEL-79243, RHEL-79246, RHEL-79251,
RHEL-79252):
- Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-02) at
revision 0x38;
- Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-02) at
@ -1203,7 +1223,7 @@ Resolves: RHEL-151645
* Tue Nov 19 2024 Eugene Syromiatnikov <esyr@redhat.com> - 4:20241112-1
- Update Intel CPU microcode to microcode-20241112 release, addresses
CVE-2024-21820, CVE-2024-21853, CVE-2024-23918, CVE-2024-23984 (RHEL-67344):
CVE-2024-21820, CVE-2024-21853, CVE-2024-23918, CVE-2024-23984 (RHEL-67336):
- Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in
intel-ucode/06-8f-05) from revision 0x2b0005c0 up to 0x2b000603;
- Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b0005c0
@ -1317,7 +1337,7 @@ Resolves: RHEL-151645
* Mon Sep 23 2024 Eugene Syromiatnikov <esyr@redhat.com> - 4:20240910-1
- Update Intel CPU microcode to microcode-20240910 release, addresses
CVE-2024-23984, CVE-2024-24853, CVE-2024-24968, CVE-2024-24980,
CVE-2024-25939 (RHEL-59081):
CVE-2024-25939 (RHEL-58057):
- Update of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode (in
intel-06-8c-01/intel-ucode/06-8c-01) from revision 0xb6 up to 0xb8;
- Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode (in
@ -1443,8 +1463,8 @@ Resolves: RHEL-151645
- Update Intel CPU microcode to microcode-20240531 release, addresses
CVE-2023-22655, CVE-2023-23583. CVE-2023-28746, CVE-2023-38575,
CVE-2023-39368, CVE-2023-42667, CVE-2023-43490, CVE-2023-45733,
CVE-2023-46103, CVE-2023-49141 (RHEL-30859, RHEL-30862, RHEL-30865,
RHEL-30868, RHEL-30871, RHEL-41093, RHEL-41108):
CVE-2023-46103, CVE-2023-49141 (RHEL-30861, RHEL-30864, RHEL-30867,
RHEL-30870, RHEL-30873, RHEL-41094, RHEL-41109):
- Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c;
- Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-02) at
revision 0x4121;
@ -1818,8 +1838,8 @@ Resolves: RHEL-151645
* Thu Aug 10 2023 Eugene Syromiatnikov <esyr@redhat.com> - 4:20230808-1
- Update Intel CPU microcode to microcode-20230808 release, addresses
CVE-2022-40982, CVE-2022-41804, CVE-2023-23908 (#2213125, #2223993, #2230678,
#2230690):
CVE-2022-40982, CVE-2022-41804, CVE-2023-23908 (#2213124, #2223992, #2230677,
#2230689):
- Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006f05 up
to 0x2007006;
@ -2019,7 +2039,7 @@ Resolves: RHEL-151645
to 0x11 (old pf 0x1).
* Mon Aug 07 2023 Eugene Syromiatnikov <esyr@redhat.com> - 4:20230516-1
- Update Intel CPU microcode to microcode-20230516 release (#2213125):
- Update Intel CPU microcode to microcode-20230516 release (#2213124):
- Addition of 06-be-00/0x01 (ADL-N A0) microcode at revision 0x10;
- Addition of 06-9a-04/0x40 (AZB A0) microcode at revision 0x4;
- Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
@ -2192,19 +2212,19 @@ Resolves: RHEL-151645
* Tue Aug 01 2023 Eugene Syromiatnikov <esyr@redhat.com> - 4:20230214-4
- Avoid spurious find failures due to calls on directories that may not exist
(#2231065).
(#2225681).
* Wed Jun 28 2023 Eugene Syromiatnikov <esyr@redhat.com> - 4:20230214-3
- Force locale to C in check_caveats, reload_microcode, and update_ucode
(#2218096).
(#2218104).
* Tue Jun 06 2023 Eugene Syromiatnikov <esyr@redhat.com> - 4:20230214-2
- Cleanup the dangling symlinks in update_ucode (#2135376).
- Cleanup the dangling symlinks in update_ucode (#2213022).
* Wed Feb 15 2023 Eugene Syromiatnikov <esyr@redhat.com> - 4:20230214-1
- Update Intel CPU microcode to microcode-20230214 release, addresses
CVE-2022-21216, CVE-2022-33196, CVE-2022-33972, CVE-2022-38090 (#2171234,
#2171259):
CVE-2022-21216, CVE-2022-33196, CVE-2022-33972, CVE-2022-38090 (#2171237,
#2171262):
- Addition of 06-6c-01/0x10 (ICL-D B0) microcode at revision 0x1000211;
- Addition of 06-8f-04/0x87 (SPR-SP E0/S1) microcode at revision
0x2b000181;
@ -2380,11 +2400,11 @@ Resolves: RHEL-151645
* Tue Oct 25 2022 Eugene Syromiatnikov <esyr@redhat.com> - 4:20220809-2
- Change the logger severity level to warning to align with the kmsg one
(#2136224).
(#2136506).
* Tue Aug 09 2022 Eugene Syromiatnikov <esyr@redhat.com> - 4:20220809-1
- Update Intel CPU microcode to microcode-20220510 release, addresses
CVE-2022-21233 (#2115667):
CVE-2022-21233 (#2115663):
- Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode (in
intel-06-55-04/intel-ucode/06-55-04) from revision 0x2006d05 up
to 0x2006e05;
@ -2447,7 +2467,8 @@ Resolves: RHEL-151645
* Tue May 10 2022 Eugene Syromiatnikov <esyr@redhat.com> - 4:20220510-1
- Update Intel CPU microcode to microcode-20220510 release, addresses
CVE-2022-0005, CVE-2022-21131, CVE-2022-21136, CVE-2022-21151 (#2086743):
CVE-2022-0005, CVE-2022-21131, CVE-2022-21136, CVE-2022-21151 (#2090248,
#2090261, #2086751, #2040069):
- Addition of 06-97-02/0x03 (ADL-HX C0) microcode at revision 0x1f;
- Addition of 06-97-05/0x03 (ADL-S 6+0 K0) microcode (in
intel-ucode/06-97-02) at revision 0x1f;
@ -2570,13 +2591,8 @@ Resolves: RHEL-151645
to 0x53.
* Thu Feb 10 2022 Eugene Syromiatnikov <esyr@redhat.com> - 4:20220207-1
- Update Intel CPU microcode to microcode-20220207 release:
- Fixes in releasenote.md file.
* Mon Feb 07 2022 Eugene Syromiatnikov <esyr@redhat.com> - 4:20220204-1
- Update Intel CPU microcode to microcode-20220204 release, addresses
CVE-2021-0127, CVE-2021-0145, and CVE-2021-33120 (#1971906, #2049543,
#2049554, #2049571):
- Update Intel CPU microcode to microcode-20220207 release, addresses
CVE-2021-0127, CVE-2021-0145, and CVE-2021-33120 (#2053253):
- Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f;
- Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04)
at revision 0xb00000f;
@ -2680,6 +2696,10 @@ Resolves: RHEL-151645
- Update of 06-a7-01/0x02 (RKL-S B0) microcode from revision 0x40 up
to 0x50.
* Mon Aug 09 2021 Mohan Boddu <mboddu@redhat.com> - 4:20210608-2
- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688
* Mon Jul 05 2021 Eugene Syromiatnikov <esyr@redhat.com> - 4:20210608-1
- Update Intel CPU microcode to microcode-20210608 release (#1921773):
- Fixes in releasenote.md file.